Merge pull request #4731 from Infisical/daniel/display-arn-on-aws-failed-auth

fix(aws-auth): better error logging
This commit is contained in:
Daniel Hougaard
2025-10-23 15:13:20 +04:00
committed by GitHub

View File

@@ -21,6 +21,7 @@ import {
UnauthorizedError UnauthorizedError
} from "@app/lib/errors"; } from "@app/lib/errors";
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip"; import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
import { logger } from "@app/lib/logger";
import { ActorType, AuthTokenType } from "../auth/auth-type"; import { ActorType, AuthTokenType } from "../auth/auth-type";
import { TIdentityDALFactory } from "../identity/identity-dal"; import { TIdentityDALFactory } from "../identity/identity-dal";
@@ -147,6 +148,8 @@ export const identityAwsAuthServiceFactory = ({
if (identityAwsAuth.allowedPrincipalArns) { if (identityAwsAuth.allowedPrincipalArns) {
// validate if Arn is in the list of allowed Principal ARNs // validate if Arn is in the list of allowed Principal ARNs
const formattedArn = extractPrincipalArn(Arn);
const isArnAllowed = identityAwsAuth.allowedPrincipalArns const isArnAllowed = identityAwsAuth.allowedPrincipalArns
.split(",") .split(",")
.map((principalArn) => principalArn.trim()) .map((principalArn) => principalArn.trim())
@@ -155,13 +158,18 @@ export const identityAwsAuthServiceFactory = ({
// considers exact matches + wildcard matches // considers exact matches + wildcard matches
// heavily validated in router // heavily validated in router
const regex = new RE2(`^${principalArn.replaceAll("*", ".*")}$`); const regex = new RE2(`^${principalArn.replaceAll("*", ".*")}$`);
return regex.test(extractPrincipalArn(Arn)); return regex.test(formattedArn);
}); });
if (!isArnAllowed) if (!isArnAllowed) {
logger.error(
`AWS Auth Login: AWS principal ARN not allowed [principal-arn=${formattedArn}] [raw-arn=${Arn}] [identity-id=${identity.id}]`
);
throw new UnauthorizedError({ throw new UnauthorizedError({
message: "Access denied: AWS principal ARN not allowed." message: `Access denied: AWS principal ARN not allowed. [principal-arn=${formattedArn}]`
}); });
}
} }
const identityAccessToken = await identityAwsAuthDAL.transaction(async (tx) => { const identityAccessToken = await identityAwsAuthDAL.transaction(async (tx) => {